Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should organisations do first to prepare access…
Governance, Ownership & Risk

What should organisations do first to prepare access controls for CMMC Phase 2?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Governance, Ownership & Risk

Start by identifying where network-level trust still substitutes for explicit access policy, then close the biggest evidence gaps in remote access, third-party connectivity and sensitive environment segmentation. The first priority is not new documentation, but demonstrable control enforcement.

Where CMMC Phase 2 access controls usually need the first fix

The best first move is to find places where access still relies on network location, shared trust zones or “who can reach it” assumptions instead of a defined policy decision. That is where Phase 2 evidence tends to fail: remote access, third-party paths and sensitive enclaves often exist, but enforcement is inconsistent or hard to prove.

In practice, this means inventorying the access paths that matter most, then checking whether each one has explicit approval, role logic, strong authentication and a reviewable decision trail. If an access path exists only because it sits inside a trusted segment, it is already a control gap.

How to prioritise the first control work

Start with the highest-value environments and the highest-risk paths, not with the most visible policy document. The first pass should identify which users, vendors, administrators and service pathways can touch controlled data or sensitive environments, and whether those pathways are actually bounded by policy rather than by topology.

For many organisations, that means separating three questions: who is allowed in, from where they are allowed to connect, and what they are allowed to reach once inside. When those are blended into one “trusted network” assumption, access control becomes difficult to test and even harder to evidence during assessment.

Strong first priorities are the places where access decisions are most likely to be challenged by an assessor: remote administration, external support access, production-to-test exceptions, and any environment that contains regulated or sensitive data. Those are the areas where control design and control evidence should line up early.

What good looks like when access controls are ready for Phase 2

Readiness is less about having a complete policy library and more about being able to prove that access is constrained in a repeatable way. A control is more credible when it shows explicit role or rule-based decisions, reviewed exceptions, and logging that demonstrates enforcement instead of intent.

That also means the organisation can explain why a given access path exists, who approved it, how it is limited, and how it is removed. If the answer depends on informal knowledge, inherited network trust, or manual workarounds, the control may exist on paper but not in operation.

For Phase 2, assessors usually care most about whether the organisation can show that access to controlled environments is not broadly open by default. The practical test is whether access changes are deliberate, bounded, and traceable, especially where third parties or privileged users are involved.

Risk and Threat Considerations

When access control depends on network trust, a compromise or misroute can turn into broad internal exposure very quickly. The risk is not just unauthorised login, it is that one weakly governed path can expose multiple sensitive systems, especially where remote access, vendor access or segmented environments are poorly separated.

Failure mechanism: Attackers or careless users can exploit inherited trust, overly broad connectivity, or missing policy enforcement to move from an allowed entry point into protected environments without a meaningful access decision at each step.

Impact: That creates overreach, weak auditability, and a larger blast radius if a credential, vendor session, or admin path is abused. It also leaves the organisation with weak evidence that access is controlled rather than merely reachable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-3 — Access EnforcementPhase 2 readiness depends on enforcing explicit access decisions, not implicit network trust.
AC-17 — Remote AccessRemote access is one of the first areas where Phase 2 evidence gaps commonly appear.
AC-20 — Use of External Information SystemsThird-party connectivity is a core first-pass risk area for access-control readiness.
Recommendation — Implement AC-3 so access is evaluated and enforced by policy at each protected boundary. Constrain remote access with explicit authorization, strong authentication, and auditable control points. Restrict and monitor external system access to controlled environments with documented conditions.
CIS Controls v8CIS-6 — Access Control ManagementAccess control management is the central control family for closing policy and enforcement gaps.
Recommendation — Centralize access control decisions and remove reliance on inherited network trust.
ISO/IEC 27001:2022A.5.15 — Access controlThe question is about establishing explicit access control requirements and enforcement.
Recommendation — Define and enforce access rules for each protected environment and access path.

Practitioner Guidance

What to verify first: Validate the access paths that can reach controlled data or sensitive systems, then confirm each one has an explicit decision point, not just a permitted route. If a path cannot produce evidence of who approved it, what it can reach, and how it is restricted, treat it as the first remediation candidate.

Decision rule: If the current control depends on segmentation or trusted connectivity to compensate for missing policy logic, prioritise replacing that dependency with enforceable access decisions before chasing lower-risk documentation gaps.

Practitioner takeaway: For cmmc phase 2, the fastest progress usually comes from converting implicit network trust into explicit, provable access enforcement, because that is where both compliance evidence and real security improve at the same time.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org